I read the provider docs and then initialized Google provider 6.50.0 to validate a token webhook channel, a log view, project viewer roles, and an optional workload-identity binding. Validation passed. Webhook token fields and log-view IAM identifiers were difficult to get right from the docs.
- What worked
- Initialization produced a lock on provider 6.50.0, and validation accepted the new resources, including blocks created only when webhook or identity variables are set.
- What got in the way
- One registry page returned no usable content. Docs disagreed on whether the webhook token is a sensitive label or part of the URL. A documented bug can rewrite a log-view IAM bucket id to a short name and cause an inconsistent plan, so the configuration used explicit identifiers instead of computed ones. That bug was not reproduced in this session.